Cyberattacks on commercial vessels have reached a new level of risk. The crew of the LNG carrier Vivit Africa LNG has stated that attackers temporarily gained control of several critical systems responsible for cargo-tank pressure and the safe transport of liquefied natural gas.
The incident occurred in early September, as the Liberia-flagged vessel sailed from Louisiana toward the Adriatic LNG terminal near Rovigo, Italy. Crew members reported that, before entering port, they lost normal access to internal control systems and later attributed the malfunction to a cyberattack. Splash247 first reported that the crew claims hackers seized control of the LNG carrier’s safety systems.
What the Crew Says Happened
By the sailors’ account, the attackers temporarily controlled the tank pressure-monitoring system and the safety valves, and also disrupted the cycle for processing boil-off gas. For an LNG tanker, this circuit is especially critical: part of the cargo constantly turns to gas, so the automation must keep the pressure within safe limits.
The crew also reported disruptions in the steam pressure systems and protective valves. In the sailors’ assessment, the combination of such failures could have raised the risk of damage to the cargo tanks and an explosion. No actual tank rupture, fire, or leak occurred, and the claimed seizure of critical systems has not yet been confirmed by independent technical data.
A More Cautious Italian Account
The Italian Coast Guard described the incident more cautiously. By its version, a malfunction arose in the systems monitoring cargo parameters aboard the vessel, after which the intervention of technical specialists was required. Official confirmation of a cyberattack specifically from the Italian authorities has not yet appeared. Korean Register received notice of the incident and continues its inquiry.
Vivit Africa LNG did not unload at Rovigo, lingered for a time off the Italian coast, and then turned west. The vessel was later directed toward Spain. The case became the third reported cyber incident involving a fuel tanker within a few weeks, once again illustrating why shipboard systems are becoming a distinct target for attackers.
Two Earlier Incidents: VL Prosperity and Kohaku
The two previous episodes involved the VL Prosperity and the Kohaku. The US Coast Guard and FBI confirmed that in August they dispatched special teams to both vessels following signs that their networks had been compromised by foreign hackers. American authorities examined both the vessels’ ordinary IT infrastructure and their operational control systems, and in the FBI/Coast Guard cases, CISA noted the actors behind those incidents did not appear to have actually taken control, unlike the Vivit Africa crew’s account of hijacked valves. TechCrunch reported that the FBI and Coast Guard boarded the hacked oil tankers heading toward the US coast.
The most detailed claims regarding the VL Prosperity came from Iranian state media, which alleged interference with communications, engine cooling, speed, and fuel systems. The US Coast Guard reported that, after the threats were addressed, it found no danger to the crew, no instability of the vessel, no environmental damage, and no operational failures.
A Possible Iran Link, and 20 Ships Under Watch
American agencies are examining a possible connection between the first two attacks and Iran-linked groups, though there is as yet no public attribution. Amid this series of incidents, US authorities have begun tracking roughly 20 commercial vessels. Anthropic earlier disclosed the activity of an Iran-linked operator that gathered information on maritime equipment and known vulnerabilities. No connection between that operation and the current incidents has been established.
An Ongoing Investigation, Not a Confirmed Sabotage
The Vivit Africa LNG story remains an investigated incident rather than a confirmed case of physical sabotage. The chief new detail concerns the alleged depth of the intrusion: the crew described access to pressure circuits and emergency valves, that is, to the very equipment on which the safety of the LNG cargo directly depends.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.